Policy & Regulation
US charges American with wiping phone using 'duress' password
The U.S. Justice Department has charged Atlanta man Samuel Tunick with allegedly wiping his phone using a 'duress' passcode during a border search, thought to be the first case.
The U.S. Justice Department is prosecuting Atlanta resident Samuel Tunick for allegedly giving U.S. border agents a passcode that wiped his phone’s contents, according to an indictment and media reports. It’s thought to be the first known U.S. case in which federal prosecutors have charged someone over the alleged destruction of data using a “duress” password built into a phone’s software. The case centers on a feature in GrapheneOS, a custom Android operating system that runs in place of the standard software on most modern Google Pixel phones; Tunick’s attorneys confirmed GrapheneOS was running on his device. The feature lets an owner set a passcode that deliberately wipes the phone if entered instead of the normal unlock code.
The indictment accuses Tunick of providing border agents a passcode that caused the phone to “delete the digital contents” before it was seized. Prosecutors charged him under a federal statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it, and Tunick has pleaded not guilty. Tunick’s attorneys, per coverage of Monday’s first hearing, argue that U.S. Customs and Border Protection’s seizure of his phone was unlawful and that all evidence — including the alleged wipe — should be suppressed. Their motion says CBP pulled Tunick into secondary inspection at Atlanta’s Hartsfield-Jackson airport as he returned from overseas on January 24, 2025, and repeatedly denied him access to an attorney without informing him of his legal rights.
The attorneys accuse the government of demanding phone access under the pretext of searching for child exploitation imagery, without providing evidence to justify that suspicion, while actually investigating Tunick’s ties to Defend the Atlanta Forest, a movement opposing Atlanta’s “Cop City” law-enforcement training campus. The motion says agents claimed they needed no warrant because Tunick had not yet crossed the border — the U.S. government has long asserted it can search and seize devices without a warrant until a person is admitted entry. When Tunick entered the passcode, “the screen went blank, flashed several times and the phone appeared to restart”; agents seized the phone anyway, then told him he was free to enter the country.
Matthew Dodge, an assistant federal public defender on Tunick’s team, called it rare to see this statute used this way. Security experts, including the Electronic Frontier Foundation’s Bill Budington and Granitt founder Runa Sandvik, said they hadn’t seen a case involving a duress password like this before. “I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it’s better to not have that data on you when you cross certain borders,” Sandvik said. The Atlanta federal court overseeing the case is expected to rule on the suppression motion later this year; a Justice Department spokesperson did not respond to a request for comment.
Why it matters
The case could set an early precedent for how “duress” data-wipe features are treated under U.S. law, and it sharpens an unresolved question digital-security advocates have long flagged: how much protection travelers’ devices actually have at the border.